
Staff Application Security Engineer β M&A
Posted 7 hours ago

Posted 7 hours ago
This is a fully remote position, open to applicants in California, +2 more states.
β’ Oversee pre-close security due diligence on potential acquisitions β manage external penetration testing, evaluate the target's architecture through threat modeling, assess security controls, and present the security risk summary to leadership prior to closing and integration planning.
β’ Facilitate post-close security integration β establish static and dynamic analysis coverage on acquired codebases, monitor high- and critical-severity issues to resolution, incorporate acquired assets into the bug bounty program, and integrate repositories into Anthropic's automated vulnerability remediation and reporting systems.
β’ Collaborate with related security engineering teams (supply chain, cloud, corporate security, detection & response) regarding their responsibilities in each integration.
β’ Engage with a diverse group of stakeholders on every acquisition β including corporate development, legal, security leadership, and the engineering teams tasked with handling the acquired systems internally; as well as engineering and security teams at the target company externally β facilitating communication and ensuring the security workstream is clear to all parties involved.
β’ Develop and expand Anthropic's M&A security playbook β including risk-scoring models, diligence runbooks, and integration checklists β and automate as many processes as possible using Claude-powered tools instead of relying solely on manual methods.
β’ Participate in the teamβs operational on-call rotation (bug bounty escalations, launch consultations, incident response), providing coverage during active deal periods.
β’ Contribute to essential AppSec projects during inter-deal periods β secure design reviews, threat modeling for agentic systems, and the teamβs security automation roadmap.
β’ Practical experience in application and infrastructure security, particularly in cloud and containerized environments.
β’ Proven ability to swiftly evaluate an unfamiliar codebase or architecture and generate a clear, prioritized risk assessment suitable for a non-security audience.
β’ Proficiency in production-level coding in at least one of the following languages: Python, Go, Rust, or TypeScript.
β’ Hands-on threat modeling and vulnerability identification skills β you have successfully discovered and analyzed real bugs in actual systems.
β’ Ability to operate with a high degree of autonomy, navigate ambiguity, and handle sensitive confidential information.
β’ Strong written and verbal communication skills tailored to diverse audiences β including executives, legal and corporate development partners, and engineering counterparts at an acquired organization.
β’ Competitive compensation and benefits.
β’ Optional equity donation matching.
β’ Generous vacation and parental leave.
β’ Flexible working hours.
β’ Pleasant office environment for collaboration.
ImagineX
11:11 SYSTEMS
Red River
Gainwell Technologies
Get handpicked remote jobs straight to your inbox weekly.